Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | KindeditorAISem-cms SemcmsAI | 23/9/2026 | 24/9/2026 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Modificada | Media (6.1) | 0.52% | — | Kindsoft Kindeditor | 11/8/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.99% | — | Kindsoft Kindeditor | 14/10/2021 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html. | |
| Modificada | Media (6.1) | 0.94% | — | Kindsoft Kindeditor | 14/10/2021 | 17/6/2026 | Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed). | |
| Modificada | Media (6.1) | 0.58% | — | Kindsoft Kindeditor | 28/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information. | |
| Modificada | Media (6.1) | 0.69% | — | Kindsoft Kindeditor | 28/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in KindEditor (Chinese versions) 4.1.12, which can be exploited by an attacker to obtain user cookie information. | |
| Modificada | Media (6.1) | 3.2% | — | Kindsoft Kindeditor | 6/2/2019 | 17/6/2026 | In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 2.1% | — | Kindeditor | 5/11/2018 | 17/6/2026 | KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication. | |
| Modificada | Media (4.3) | 1.3% | — | Kindsoft Kind EditorKindsoft Kindeditor | 14/9/2017 | 17/6/2026 | Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files. |